Debian Security Advisory
DLA-1528-1 strongswan -- LTS security update
- Date Reported:
- 02 Oct 2018
- Affected Packages:
- strongswan
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-17540.
- More information:
-
It was discovered that there was a denial-of-service vulnerability in strongswan, a virtual private network (VPN) client and server.
Verification of an RSA signature with a very short public key caused an integer underflow in a length check that resulted in a heap buffer overflow.
For Debian 8
Jessie
, this issue has been fixed in strongswan version 5.2.1-6+deb8u8.We recommend that you upgrade your strongswan packages.